Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
30355
Total
2427
Critical
9086
High
9450
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-40897 | HIGH | 8.8 | Math.js is an extensive math library for JavaScript and Node.js. From 13.1.1 to before 15.2.0, a vulnerability allowed executing arbitrary JavaScript via the expression parser … | Apr 24, 2026 |
| CVE-2026-40609 | UNKNOWN | — | Rejected reason: This CVE is a duplicate of another CVE. | Apr 24, 2026 |
| CVE-2026-39920 | CRITICAL | 9.8 | BridgeHead FileStore versions prior to 24A (released in early 2024) expose the Apache Axis2 administration module on network-accessible endpoints with default credentials that allows unauthenticated … | Apr 24, 2026 |
| CVE-2026-30368 | UNKNOWN | — | A client-side authorization flaw in Lightspeed Classroom v5.1.2.1763770643 allows unauthenticated attackers to impersonate users by bypassing integrity checks and abusing client-generated authorization tokens, leading to … | Apr 24, 2026 |
| CVE-2025-67259 | MEDIUM | 6.5 | A Broken Access Control vulnerability exists in ClassroomIO v0.1.13 where an authenticated low-privileged "student" user can access unauthorized course-level information by modifying intercepted API requests. … | Apr 24, 2026 |
| CVE-2025-59308 | MEDIUM | 4.7 | In Mahara before 24.04.10 and 25 before 25.04.1, an institution administrator or institution support administrator on a multi-tenanted site can masquerade as an institution member … | Apr 24, 2026 |
| CVE-2026-42095 | MEDIUM | 4.0 | bookserver in KDE Arianna before 26.04.1 allows attackers to read files over a socket connection by guessing a URL. | Apr 24, 2026 |
| CVE-2026-31672 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: rt2x00usb: fix devres lifetime USB drivers bind to USB interfaces and any device managed … | Apr 24, 2026 |
| CVE-2026-31671 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm_user: fix info leak in build_report() struct xfrm_user_report is a __u8 proto field followed by … | Apr 24, 2026 |
| CVE-2026-31670 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: rfkill: prevent unlimited numbers of rfkill events from being created Userspace can create an … | Apr 24, 2026 |
| CVE-2026-31669 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: mptcp: fix slab-use-after-free in __inet_lookup_established The ehash table lookups are lockless and rely on SLAB_TYPESAFE_BY_RCU … | Apr 24, 2026 |
| CVE-2026-31668 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: seg6: separate dst_cache for input and output paths in seg6 lwtunnel The seg6 lwtunnel uses … | Apr 24, 2026 |
| CVE-2026-31667 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: Input: uinput - fix circular locking dependency with ff-core A lockdep circular locking dependency warning … | Apr 24, 2026 |
| CVE-2026-31666 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: btrfs: fix incorrect return value after changing leaf in lookup_extent_data_ref() After commit 1618aa3c2e01 ("btrfs: simplify … | Apr 24, 2026 |
| CVE-2026-31665 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: netfilter: nft_ct: fix use-after-free in timeout object destroy nft_ct_timeout_obj_destroy() frees the timeout object with kfree() … | Apr 24, 2026 |
| CVE-2026-31664 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: clear trailing padding in build_polexpire() build_expire() clears the trailing padding bytes of struct xfrm_user_expire … | Apr 24, 2026 |
| CVE-2026-31663 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: xfrm: hold dev ref until after transport_finish NF_HOOK After async crypto completes, xfrm_input_resume() calls dev_put() … | Apr 24, 2026 |
| CVE-2026-31662 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: tipc: fix bc_ackers underflow on duplicate GRP_ACK_MSG The GRP_ACK_MSG handler in tipc_group_proto_rcv() currently decrements bc_ackers … | Apr 24, 2026 |
| CVE-2026-31661 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: brcmsmac: Fix dma_free_coherent() size dma_alloc_consistent() may change the size to align it. The new … | Apr 24, 2026 |
| CVE-2026-31660 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: nfc: pn533: allocate rx skb before consuming bytes pn532_receive_buf() reports the number of accepted bytes … | Apr 24, 2026 |
| CVE-2026-31659 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: reject oversized global TT response buffers batadv_tt_prepare_tvlv_global_data() builds the allocation length for a global … | Apr 24, 2026 |
| CVE-2026-31658 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: net: altera-tse: fix skb leak on DMA mapping error in tse_start_xmit() When dma_map_single() fails in … | Apr 24, 2026 |
| CVE-2026-31657 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: batman-adv: hold claim backbone gateways by reference batadv_bla_add_claim() can replace claim->backbone_gw and drop the old … | Apr 24, 2026 |
| CVE-2026-31656 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: drm/i915/gt: fix refcount underflow in intel_engine_park_heartbeat A use-after-free / refcount underflow is possible when the … | Apr 24, 2026 |
| CVE-2026-31655 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: pmdomain: imx8mp-blk-ctrl: Keep the NOC_HDCP clock enabled Keep the NOC_HDCP clock always enabled to fix … | Apr 24, 2026 |